Ransomware readiness for a small office
For office managers, IT generalists and MSP technicians who look after the IT of a small office (roughly 5 to 50 people) and need it to be ready for ransomware before it happens. Complete 'Backup resilience against ransomware' first: this course refers to offline backups and restore testing but doesn't reteach them. You'll prioritise prevention by the ways attackers usually get in, run a readiness self-assessment and record the gaps, write a short response plan and an offline contact card, choose the first actions when ransomware is found, and plan reporting and the payment question. It follows the US #StopRansomware Guide (CISA, FBI, NSA and MS-ISAC) and UK NCSC guidance, with US and UK reporting routes. The technician's detailed first hour is covered in 'Incident response: the first hour for an MSP technician'. Notification duties and the legality of payments depend on law, contract and insurance terms: this course is not legal advice and doesn't grant any certification.
- Level
- Intermediate
- Length
- About 105 minutes
- Contents
- 5 lessons · final exam
- Status
- Published · updated 10 Oct 2026
Skills you'll practise
- Identify the initial access routes ransomware actors commonly use and prioritise prevention controls for a small office
- Assess a small office's ransomware readiness against a checklist and record the gaps
- Write a ransomware response plan and an offline contact card that names who decides and who to call
- Choose the first response actions from the ransomware response checklist, including isolation and evidence preservation
- Choose reporting routes and explain the payment position of law enforcement, insurers and legal advisers
Course outline
- 1.Identify the initial access routes ransomware actors use and prioritise prevention controlsLesson · 22 min
- 2.Assess a small office's ransomware readiness against a checklist and record the gapsLesson · 20 min
- 3.Write a ransomware response plan and an offline contact card that names who decidesLesson · 20 min
- 4.Choose the first response actions from the ransomware response checklist, including isolation and evidenceLesson · 18 min
- 5.Choose reporting routes and explain the payment position of law enforcement, insurers and legal advisersLesson · 15 min
- 6.Ransomware readiness for a small office: knowledge checkKnowledge check · 15 questions
- 7.Ransomware readiness for a small office: practical exerciseKnowledge check · 1 question
- 8.Final exam10 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- CISA, FBI, NSA and MS-ISAC: #StopRansomware Guide (US; updated September 2023)
- NCSC: Mitigating malware and ransomware attacks (UK, version 3.0)
- NCSC: What you need to know about ransomware (UK)
- NCSC with ABI, BIBA and IUA: Guidance for organisations considering payment in ransomware incidents (UK, 2024)
- FBI: Ransomware (US)
- FBI Internet Crime Complaint Center (IC3): home page (US)
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.